Files
youssefnoob003-SindriKit/docs/architecture/README.md
T
sibouzitoun aea2eb6cfb Release v1.1.0: Process Injection & Architecture Hardening
- Implement complete cross-process injection engine via snd_inj_ctx_t
- Track explicit remote_entry_point for safe thread hijacking and PE execution
- Refactor standalone syscall resolvers into a unified pipeline (scan/sort)
- Perfect status code system by purging generic fallbacks in favor of highly-specific, domain-aware error codes
- Fix minor pointer validation and parsing bugs in the reflective loader
2026-06-28 14:14:54 +01:00

2.7 KiB

Core Architecture

Design patterns, execution models, and telemetry constraints governing SindriKit.

Caution

No direct OS calls in domain logic. Host interaction goes through injected API tables or explicitly bootstrapped execution layers (syscall pipeline, FFI bridges).

Framework layers

┌─────────────────────────────────────────────────────────────┐
│  Application / implant / PoC                                 │
└───────────────────────────┬─────────────────────────────────┘
                            ▼
┌─────────────────────────────────────────────────────────────┐
│  Domains: loaders · injection · (future) evasion           │
└───────────────────────────┬─────────────────────────────────┘
                            ▼
┌─────────────────────────────────────────────────────────────┐
│  Primitives + execution (DI tables, syscalls, FFI)         │
└───────────────────────────┬─────────────────────────────────┘
                            ▼
┌─────────────────────────────────────────────────────────────┐
│  Parsers · Common                                            │
└─────────────────────────────────────────────────────────────┘

Table of Contents